04-29-2021 03:51 AM
Hi all,
Do you know if FMC and FTD support ISE Tacacs+ device administration integration? So far, I did the router/switch and ASA integrations, but not able to find resources for the noted FTD and FMC ones!
Looking forward to hearing any thoughts or suggestions.
Thank you,
Laura
Solved! Go to Solution.
04-29-2021 04:12 AM
how about using Radius ? as of i have tested 6.2
May be need to read what 6.7 (any update on that)
04-29-2021 04:33 AM
No TACACS+ is still not supported on the FMC, you can use RADIUS.
Use the "class" RADIUS attributes in AuthZ profiles.
Class=Administrator
or
Class=SecAnalyst
And map these to roles in the FMC (System > Users > External Authentication).
So for example on the FMC if you want to configure the Security Analyst role then define Class=SecAnalyst or for administrator role define Class=Administrator.
HTH
04-29-2021 05:17 AM
Its for both, you can use Radius only with Attributes mentioned also provided link have all the information
any issue please let us know, happy to assists further.
04-29-2021 05:28 AM
The RADIUS attributes values previously provided where for FMC. Use the following in AuthZ profile for FTDs
"Radius:Service-Type = Administrative (6)" << for Administrator
"Radius:Service-Type = Login (1)" << for non-administrator
04-29-2021 07:49 AM
As the others have noted - plus make sure you tick the box to include shell authentication to make the setting apply to the cli logins on FMC and FTD. That's not selected by default.
04-29-2021 04:12 AM
how about using Radius ? as of i have tested 6.2
May be need to read what 6.7 (any update on that)
04-29-2021 04:33 AM
No TACACS+ is still not supported on the FMC, you can use RADIUS.
Use the "class" RADIUS attributes in AuthZ profiles.
Class=Administrator
or
Class=SecAnalyst
And map these to roles in the FMC (System > Users > External Authentication).
So for example on the FMC if you want to configure the Security Analyst role then define Class=SecAnalyst or for administrator role define Class=Administrator.
HTH
04-29-2021 04:49 AM
Thank you for your feedback! Highly appreciated. Due to limited testing resources, I need to ask you if this is valid for only FMC or also FTD's?!
The solution you described, I found it on portals, as a solution to be enabling FMC GUI Authentication. My intentions are to do that for the CLI access of both FMC and also two FTDs
Looking forward to hearing from you.
Thank you,
Laura
04-29-2021 05:17 AM
Its for both, you can use Radius only with Attributes mentioned also provided link have all the information
any issue please let us know, happy to assists further.
04-29-2021 05:28 AM
The RADIUS attributes values previously provided where for FMC. Use the following in AuthZ profile for FTDs
"Radius:Service-Type = Administrative (6)" << for Administrator
"Radius:Service-Type = Login (1)" << for non-administrator
04-29-2021 07:49 AM
As the others have noted - plus make sure you tick the box to include shell authentication to make the setting apply to the cli logins on FMC and FTD. That's not selected by default.
05-05-2021 05:16 AM
Dear community,
Thank you very much for the support provided. I have followed your advices and resulted in a successful integration.
This community is awesome.
Thank you,
Laura
07-14-2022 08:32 AM
Hi Experts,
Is this supported in ver 6.7?
-Samarth
07-14-2022 08:40 AM
No it's not supported in any version - even in the latest version 7.2.
07-14-2022 08:40 AM
as per @laurathaqi input that works.
07-14-2022 08:53 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide